Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm working on this with a private prototype. I'm probably going to lean towards using a Service Worker (https://developer.mozilla.org/en-US/docs/Web/API/Service_Wor...) to renew challenges at a reduced difficulty. Stay tuned!
 help



That just creates another problem: if you're taking any measures to reduce tracking (ie. clearing cookies on shutdown or using temporary containers), this won't work. If anubis was being deployed on a site that a user visits often (eg. HN), the user might be convinced to whitelist it, but most anubis deployments are on random blogs or fediverse instances that I might not visit again in months. I'm certainly am not going to whitelist those sites, nor am I going to enable cookies wholesale just to avoid solving challenges.

Look, if you're going out of your way to break expected behaviour on websites you shouldn't be surprised when people code to the most common denominator and then you have weird subtle breakage as a result.

Gotta agree. Turning tracking cookies off? Sure! Turning session cookies off and then complaining that the server doesn’t remember you? Uhhh…

And while I’m sympathetic to the idea of not wanting to run JS, to a first approximation modern browsers are JS engines that have graphical displays. How things should be vs how they are is a classic is/ought problem. The world took a vote on what a browser’s meant for and we lost. Fighting it today is rough; tomorrow, futile.


>Gotta agree. Turning tracking cookies off? Sure! Turning session cookies off and then complaining that the server doesn’t remember you? Uhhh…

No, because there are technologies that don't have this issue, eg. privacy pass.


There's no mechanistic difference between the two types of cookies, let's not pretend this is an actual config choice that people are making.

Whenever I hit Anubis, I simply go "keep your secrets then" and take my leave. The vast majority of the sites posted to HN (that catch my fancy) work fine or fine enough, and are better for it.

If I really, really desperately want to check something out, I can always just turn stuff back on. Turns out, I rarely do.

Shoutout to the particularly dogshit few that don't just require cookies and JS, but even third party JS. For reading a blogpost or a message thread!


> There's no mechanistic difference between the two types of cookies, let's not pretend this is an actual config choice that people are making.

They probably meant 3rd party cookies. It's common to block those. 1st party cookies not so much.


The Anubis anime girl is an instant tab close for me, especially while in public. I dont like having to explain to people that I'm not one of those creepy anime guys.

That’s the most insecure thing I’ve heard in a while. What other things randomly flashing across your screen disturb you? Do you imagine your coworkers keeping count of which ads are displayed in your browsers? Do you imagine that they don’t also see the Anubis loading screens?

It isn't even anime style, it gives me more western cartoonish vibes.

From someone who doesn't want to associate with it, I think 'anime girl' is fair. Even if people who consume it might (and do) categorize it otherwise.

uBlock Origin filter to block the anime girl from loading:

  ! Title: Hide Anubis Image
  */.within.website/x/cmd/anubis/static/img/*.webp$image
(c) https://news.ycombinator.com/item?id=46310941

Clearing cookies when all you want to do is read static content is not "breaking expected behaviour on websites".



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: